vciy

CVEs we hold for Octobercms

Records whose assigning authority named Octobercms as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-49400October CMS: PHP Object Injection via Backend Widget Session Storageoctobercms october
CVE-2026-46696October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Callsoctobercms system
CVE-2026-29179October: Editor Sub-Permission Bypass for Asset and Blueprint File Operationsoctobercms october
CVE-2026-27937October: Reflected XSS via DataTable Form Widgetoctobercms october
CVE-2026-26274October: Safe Mode Bypass via Twig Database Write Operationsoctobercms october
CVE-2026-26067October: Safe Mode Bypass via CSS Preprocessor Compilersoctobercms october
CVE-2026-25133October CMS has Stored XSS via SVG Filter Bypassoctobercms october
CVE-2026-25125October CMS: Environment Variable Exfiltration via INI Parser Interpolationoctobercms october
CVE-2026-24907October CMS has Stored XSS via Event Log Mail Previewoctobercms october
CVE-2026-24906October CMS has Stored XSS in its Backend Editor Markup Classesoctobercms october
CVE-2026-22692October CMS: Twig Sandbox Bypass via Collection Methodsoctobercms october
CVE-2025-61676October CMS Vulnerable to Stored XSS via Branding Stylesoctobercms october
CVE-2025-61674October CMS Vulnerable to Stored XSS via Editor and Branding Stylesoctobercms october
CVE-2024-51991October CMS Allows Unprotected SVG Rename in Media Manageroctobercms october
CVE-2024-25637Reflected XSS via X-October-Request-Handler Headeroctobercms october
CVE-2024-24764October Open Redirect for Administrator Accountsoctobercms october
CVE-2023-44383October CMS stored XSS by authenticated backend user with improper configurationoctobercms october
CVE-2023-44382October CMS safe mode bypass using Twig sandbox escapeoctobercms october
CVE-2023-44381October CMS safe mode bypass using Page template injectionoctobercms october
CVE-2022-35944October CMS Safe Mode bypass leads to authenticated RCE (Remote Code Execution)octobercms october
CVE-2022-24800Race Condition in October CMS upload processoctobercms october
CVE-2022-23655Missing server signature validation in OctoberCMSoctobercms october
CVE-2022-21705Authenticated remote code execution in octobercmsoctobercms october
CVE-2021-41126Deleted Admin Can Sign In to Admin Interfaceoctobercms october
CVE-2021-32650Arbitrary code execution in october/systemoctobercms october
CVE-2021-32649Authenticated file write leads to remote code execution in october/systemoctobercms october
CVE-2021-32648Account Takeover in Octobercmsoctobercms october
CVE-2021-29487Authentication bypass in Octobercmsoctobercms october
CVE-2021-21265October CMS vulnerable to Potential Host Header Poisoning on misconfigured serversoctobercms october
CVE-2021-21264Bypass of fix for CVE-2020-26231, Twig sandbox escapeoctobercms october
CVE-2020-5299Potential CSV Injection vector in OctoberCMSoctobercms october
CVE-2020-5298Reflected XSS when importing CSV in OctoberCMSoctobercms october
CVE-2020-5297Upload whitelisted files to any directory in OctoberCMSoctobercms october
CVE-2020-5296Arbitrary File Deletion vulnerability in OctoberCMSoctobercms october
CVE-2020-5295Local File read vulnerability in OctoberCMSoctobercms october
CVE-2020-26231Bypass of fix for CVE-2020-15247, Twig sandbox escapeoctobercms october
CVE-2020-15249Stored XSS by authenticated backend user with access to upload filesoctobercms october
CVE-2020-15248Privilege escalation by backend users assigned to the default "Publisher" system roleoctobercms october
CVE-2020-15247Twig Sandbox Escape by authenticated users with access to editing CMS templates when safemode is enabled.octobercms october
CVE-2020-15246Local File Inclusion by unauthenticated usersoctobercms october
CVE-2020-15128Reliance on Cookies without validation in OctoberCMSoctobercms october

41 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.